Scope integration test doubles alongside script-local helpers

This commit is contained in:
Shirofune-Security committed 2026-09-18 22:16:11 +09:00
1 parent 4c2193964e
commit 9bd56a0840
3 files changed
+23 -17

No files matched your search

+7 -5
View File
@@ -1,5 +1,7 @@
# Composed #362/#363/#365 behavior, using mock registry/CIM and temporary journals only.
$ErrorActionPreference = 'Stop'
# Keep mocks in the same script scope as dot-sourced helpers/imported commands;
# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks.
$repo = Split-Path $PSScriptRoot -Parent
$script:ScriptRoot = $repo
. (Join-Path $repo 'scripts/Configuration.ps1')
@@ -29,30 +31,30 @@ function Reset-Mocks($Outgoing = 0, $Domain = 2, $ProductType = 2) {
$script:writes = 0; $script:readFails = $false; $script:writeFails = ''
$script:roleFails = $false
}
function global:Get-CimInstance {
function Get-CimInstance {
param($ClassName, $Property, $Namespace, $ErrorAction)
if ($ClassName -eq 'Win32_OperatingSystem') {
if ($script:roleFails) { throw 'Mock role query failure' }
return [pscustomobject]@{ ProductType = $script:productType }
}
}
function global:Test-Path {
function Test-Path {
param($LiteralPath, $Path, $ErrorAction)
$target = if ($LiteralPath) { $LiteralPath } else { $Path }
if ($target -like 'HKLM:*') { return $true }
Microsoft.PowerShell.Management\Test-Path -LiteralPath $target
}
function global:Get-ItemProperty {
function Get-ItemProperty {
param($LiteralPath, $ErrorAction)
if ($script:readFails) { throw 'Mock registry read failure' }
return [pscustomobject]$script:registry
}
function global:Get-WelaRegistryState {
function Get-WelaRegistryState {
param($Path, $Name)
if ($script:readFails) { throw 'Mock registry read failure' }
[pscustomobject]@{ KeyExists = $true; ValueExists = ($null -ne $script:registry[$Name]); Value = $script:registry[$Name]; Type = 'DWord' }
}
function global:Set-ItemProperty {
function Set-ItemProperty {
param($LiteralPath, $Name, $Value, $Type, $ErrorAction)
# Assert the actual mutation cannot run before its matching journal entry.
$journal = Join-Path $script:currentContext.BackupPath 'before.jsonl'
@@ -1,5 +1,7 @@
# Profile command + verified configuration integration. No Windows policy is touched.
$ErrorActionPreference = 'Stop'
# Keep mocks in the same script scope as dot-sourced helpers/imported commands;
# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks.
$repo = Split-Path $PSScriptRoot -Parent
$script:ScriptRoot = $repo
Import-Module (Join-Path $repo 'modules/AuditProfiles.psm1') -Force
@@ -44,16 +46,16 @@ function Reset-Run([string]$Profile = 'cis-win11-v4-l1', [switch]$DryRun) {
$script:cleanup.Add($script:BackupPath)
$script:cleanup.Add($script:ResultsPath)
}
function global:TestWindows { return $true }
function global:TestAdministrator { return $true }
function global:Get-WelaHostContext { [pscustomobject]@{ Role = 'Client'; Build = $script:hostBuild } }
function global:Get-WelaEffectiveAuditPolicy { return $script:state.Clone() }
function global:Get-WelaNativeAuditPolicy {
function TestWindows { return $true }
function TestAdministrator { return $true }
function Get-WelaHostContext { [pscustomobject]@{ Role = 'Client'; Build = $script:hostBuild } }
function Get-WelaEffectiveAuditPolicy { return $script:state.Clone() }
function Get-WelaNativeAuditPolicy {
param($Guid)
if (-not $script:state.ContainsKey($Guid)) { throw "Mock missing policy: $Guid" }
return $script:state[$Guid]
}
function global:Invoke-WelaNative {
function Invoke-WelaNative {
param($FilePath, $Arguments)
if ($FilePath -ne 'auditpol.exe' -or $Arguments[0] -ne '/set') { throw 'Unexpected native mutation' }
$guid = ($Arguments | Where-Object { $_ -like '/subcategory:*' }) -replace '^/subcategory:\{([^}]+)\}$', '$1'
+8 -6
View File
@@ -1,6 +1,8 @@
# Safety regressions use extracted dispatcher statements with stub mutators and mocked registry APIs.
# Never dot-source WELA or invoke configure-sacl/update-rules implementations from this test.
$ErrorActionPreference = 'Stop'
# Keep mocks in the same script scope as dot-sourced helpers/imported commands;
# Windows PowerShell 5.1 resolves script-local originals ahead of global mocks.
$repo = Split-Path $PSScriptRoot -Parent
$tokens = $null; $errors = $null
$ast = [Management.Automation.Language.Parser]::ParseFile((Join-Path $repo 'WELA.ps1'), [ref]$tokens, [ref]$errors)
@@ -54,26 +56,26 @@ function New-RaceContext([switch]$Prompt) {
$script:cleanup.Add($path)
New-WelaConfigurationContext -Auto:(-not $Prompt) -BackupPath $path
}
function global:Get-WelaOutgoingNtlmState {
function Get-WelaOutgoingNtlmState {
# The first display is deliberately stale; the shared runner must trust its own fresh read.
[pscustomobject]@{ Readable = $true; Value = 0; Description = 'Allow all (initial read)'; PolicySource = 'mock' }
}
function global:Get-WelaRegistryState {
function Get-WelaRegistryState {
param($Path, $Name)
if ($script:journalWritten -and $script:prewriteReadFails) { throw 'Mock prewrite read failure' }
[pscustomobject]@{ KeyExists = $true; ValueExists = $true; Value = $script:value; Type = $script:type }
}
function global:New-WelaRegistryKey { param($Path) }
function global:Set-ItemProperty {
function New-WelaRegistryKey { param($Path) }
function Set-ItemProperty {
param($LiteralPath, $Name, $Value, $Type, $ErrorAction)
$script:value = $Value; $script:type = $Type; $script:writes++
}
function global:Read-Host {
function Read-Host {
param($Prompt)
if ($null -ne $script:changeOnPrompt) { $script:value = $script:changeOnPrompt }
return 'Y'
}
function global:Add-Content {
function Add-Content {
param($LiteralPath, $Value, $Encoding, $ErrorAction)
process {
# Preserve real temporary recovery files; only the mocked policy state changes.